This fake GIMP Google ad just ends up serving malware

x
(Image credit: Shutterstock)

Google’s advertising network has been found serving a malicious ad that might end up seeing users have their identity data and other sensitive intel stolen.

Hackers have reportedly managed to trick Google Ad Manager into serving a fake ad for popular photo editor GIMP, meaning those who wanted to download the program only ended up with a potent infostealer called Vidar. 

Whenever a victim typed in “GIMP” or a similar keyword in Google’s search engine, they’d be presented, among other things, with an ad showing GIMP’s official website - GIMP.org. However, actually clicking on the ad would not send the victim to that particular domain, but rather to gilimp.org, or gimp.monster. There, they’d be offered to download a 700MB-large file, an overinflated executable that’s actually just 5MB in size - the Vidar infostealer. 

Tricking the system

How this was possible is still not entirely certain. While some researchers think the threat actor used the IDN homograph technique to make the Cyrillic gіmp.org - typed as http://xn--gmp-jhd.org/, appear as gimp.org in the Latin alphabet, others are of the opinion that the trick is actually far less elaborate.

In fact, BleepingComputer reports that Google lets publishers create ads with two different URLs - one to serve to the viewers, and the other one where they’ll actually be taken. Allegedly, Google’s pretty strict with these things allowing, for example, only those that use the same domain. How, or why, the Ad Manager allowed this particular campaign to go live is unknown. Google is still silent on the matter, and we’ll update the article if the search giant decides to elaborate. 

Vidar is a known infostealer capable of grabbing browser information (passwords, cookies, stored credit card information, and similar), cryptocurrency wallet information, Telegram credentials, file transfer application information, and plenty of other sensitive data. 

Via. BleepingComputer

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Fraude en ligne phishing
Google Search ads are being hacked to steal account info
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Mac users targeted with new malware, so be on your guard
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
A padlock resting on a keyboard.
Understanding and avoiding malvertizing attacks
Trojan
Hackers hide malware into website images to go unnoticed
An Android phone being held in the hand
These malicious Android apps were installed over 60 million times - here's how to stay safe
Latest in Security
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
Data leak
Top collectibles site leaks personal data of nearly a million users
Spyware
Stalkerware data breach potentially hits over 2 million users, including thousands of Apple devices
An American flag flying outside the US Capitol building against a blue sky
Five Eyes "cannot replace US intel in Ukraine", claims former US Cyber Command Chief
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Criminals are using a virtual hard disk image file to host and distribute dangerous malware
Latest in News
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
A fresh Samsung Galaxy S25 Edge benchmark leak has eased my worries about its performance
Gmail at 20
Your Gmail search results are about to get a huge change - and I'm not sure you're going to be happy with it
Google Pixel 9 in green Wintergreen color showing AI features on screen
Older Pixels just got a big performance boost, while the Pixel 9a is lacking a key feature
Wonka poster
Netflix cooks up sweet new reality TV series based on Charlie and the Chocolate Factory, and it's a dream come true for me
Citroen 2CV
The retro EV resurgence is in full swing, as Citroen confirms the iconic 2CV will return with batteries
Hugging Snap
This AI app claims it can see what I'm looking at – which it mostly can